Unrestricted File Upload Vulnerability in HCL BigFix Service Management
CVE-2026-56590

6.4MEDIUM

What is CVE-2026-56590?

The HCL BigFix Service Management product is compromised by an Unrestricted File Upload vulnerability, stemming from inadequate file validation controls. This allows unauthenticated attackers the potential to upload malicious files, which can be executed to compromise the entire server, hence jeopardizing the security of the system and its data.

Affected Version(s)

HCL BigFix Service Management v27

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.